CVE-2024-50564

low

Description

A use of hard-coded cryptographic key in Fortinet FortiClientWindows version 7.4.0, 7.2.x all versions, 7.0.x all versions, and 6.4.x all versions may allow a low-privileged user to decrypt interprocess communication via monitoring named piped.

References

https://www.theregister.com/2024/11/14/fortinet_vpn_authentication_bypass_bug/

https://pentera.io/resources/research/two-zero-days-forticlient-vpn-2024/

https://fortiguard.fortinet.com/psirt/FG-IR-24-216

Details

Source: Mitre, NVD

Published: 2025-01-14

Updated: 2025-01-14

Risk Information

CVSS v2

Base Score: 1.7

Vector: CVSS2#AV:L/AC:L/Au:S/C:P/I:N/A:N

Severity: Low

CVSS v3

Base Score: 3.3

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Severity: Low